FOFA[verified]@fofabotDisclosure
Two new high‑severity CVEs (CVE‑2026‑64633 and CVE‑2026‑58075) affecting Veeam ONE, enabling unauthenticated remote code execution and file read, have been announced; a Veeam KB article is cited for remediation.
GovCERT.CZ[verified]@GOVCERT_CZDisclosure
This post discloses a critical RCE vulnerability (CVE‑2026‑64633) in Veeam ONE with a CVSS score of 10.0, affecting versions up to 13.0.2.6723, and urges users to upgrade to 13.1.0.7034 or newer.
yousukezan[verified]@yousukezanPatch
The post announces a critical RCE CVE in Veeam ONE, provides a patch and mitigation steps, but no PoC or evidence of active exploitation.
lee1981[verified]@lee1981bPatch
Veeam ONE hosts are exposed to a critical unauthenticated remote code execution vulnerability (CVE‑2026‑64633). A patch is available (13.1.0.7034); no public PoC or active exploitation has been reported.
CyberSignal | Cybersecurity News[verified]@XQOPTRXPatch
The post announces that Veeam has released patches for several ONE vulnerabilities, including the high‑severity CVE‑2026‑64633 that allows unauthenticated remote code execution, and urges users to apply the fix.
Adam[verified]@seoscottsdalePatch
The tweet announces that Veeam ONE’s critical RCE was patched, mentions a public PoC for the OVSwrap local root flaw, and highlights the vulnerability’s severity.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces CVE-2026-64633, a critical remote unauthenticated code injection flaw in Veeam ONE up to version 13.0.2, and urges users to apply the fix available via Veeam KB4892.
SecAlerts@SecAlertsCoPatch
The tweet highlights a critical unauthenticated RCE (CVE‑2026‑64633) in Veeam, noting an immediate patch is available.